Tools for Security Troubleshooting Flashcards
1
Q
Anti-virus and anti-malware software
A
- Stop malicious software from running
* Keep your signatures updated
2
Q
Recovery Console / Command Prompt
A
- Use, copy, rename, or replace OS files and folders
- Enable or disable service or device startup
- Remove malicious software components
- Windows Vista/7
- System Recovery Options / Command Prompt
- Windows 8/8.1
- Troubleshoot / Advanced options / Cmd Prompt
3
Q
System Restore
A
- Go back-in-time to correct problems
- Windows Vista and 7:
- All Programs / Accessories / System Tools / System Restore
- Windows 8/8.1:
- Control Panel / System / Advanced System Settings
- Doesn’t guarantee recovery from malware
4
Q
Windows Refresh (Windows 8/8.1)
A
- Reinstall Windows
* Keep your personal files and settings
5
Q
LVM (Linux Logical Volume Manager) snapshots
A
- The Linux version of Windows System Restore
- Common on high-availability servers
- Works very quickly
- Initial snapshot is comprehensive
- Only snapshots what’s changed
- Restore from the snapshot
- Many different file versions and points in me
6
Q
Windows Pre-installation (PE) environments
A
- A minimal Windows operating environment
- Resolve security issues, copy and recover data
- Create your own Windows Anti-malware boot disk
7
Q
Event Viewer
A
- Central event consolidation
- Get details around security events
- Authentication and application information
8
Q
MSCONFIG / System Configuration
A
- Safe boot: Minimal
- Safe mode GUI with minimal services, no network
- Safe boot: Alternate shell - with minimal services
- Safe boot: Active Directory repair
- Safe boot: Network - File explorer in safe mode